← Latest papers
🔢 mathematics

Z-Sigil: A Public-Key Cryptosystem with Chained Selection over a Fiber Bundle of Module-Lattice Keys

This paper introduces Z-Sigil, a public-key cryptosystem that chains Module-Lattice keys via a fiber bundle structure and a hash-based state update mechanism to achieve IND-CPA security under decisional Module-LWE assumptions, while providing a formal correctness proof and noise analysis without establishing authentication, chosen-ciphertext security, or concrete security levels.

Original authors: Andrea Rondelli

Published 2026-10-01✓ Author reviewed ⓘ
📖 5 min read🧠 Deep dive

Original authors: Andrea Rondelli

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). ✨ This is an AI-generated explanation of the paper below. It is not written by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

In the digital world, keeping secrets safe relies on a delicate balance between complexity and predictability. Modern encryption often uses mathematical structures called lattices, which are like vast, multi-dimensional grids of points. To hide a message, a sender scrambles it using a secret key, adding a tiny amount of random noise to the result. This noise makes the scrambled message look like random static to anyone without the key, but a person with the correct key can subtract the noise and read the original text. The security of these systems depends on the fact that finding the secret key from the noisy public information is incredibly difficult, even for powerful computers. As quantum computers threaten to break many of today's codes, researchers are constantly looking for new ways to arrange these mathematical grids to stay one step ahead.

A researcher has proposed a new way to organize these keys, moving away from the standard practice of using a single secret for an entire message. Instead of relying on one static key, their system, called Z-Sigil, uses a large family of different keys, all generated in advance. The unique feature of this design is that the message itself decides which key to use for each piece of the data. As the message is broken down into small blocks, the content of each block determines the path taken through the family of keys. This creates a dynamic journey where the order of keys is not fixed by the sender or the receiver, but is instead dictated by the data being sent. The researcher built this system on a geometric framework they describe as a bundle of keys over a flat torus, a shape that can be thought of as a doughnut surface where opposite edges connect, though in their work, this is a discrete, finite version used for calculation.

The core of the proposal is a method where the plaintext, or the readable message, acts as a guide. Before any message is sent, the system generates a fixed set of secret keys and their corresponding public versions. When a message is prepared, it is divided into 32-byte chunks. For the first chunk, the system uses a public starting point to select a key. Once that chunk is encrypted, the system uses the recovered content of that chunk to update its internal state, which then selects the key for the next chunk. This process repeats for the entire message. Because the selection of the next key depends on the content of the previous one, the path through the family of keys is unique to that specific message. If an attacker tries to guess the path without knowing the message, they face a moving target where the rules change with every step.

The researcher proved that this method works correctly under specific conditions. They showed that if the noise added during encryption stays within a certain limit, the receiver can successfully recover the message by following the same path. They calculated that for a typical message size of 64 blocks, the chance of the system failing to decode the message is vanishingly small, far less than one in a trillion trillion. Under stated decisional Module-LWE assumptions, they proved confidentiality against chosen-plaintext attacks (IND-CPA) for the complete chain, allowing messages chosen after the public key. However, they were careful to distinguish between reliability and security. While the system is highly reliable and offers IND-CPA security, they explicitly noted that the scheme provides no authentication or chosen-ciphertext security. Furthermore, they demonstrated that if an attacker manages to learn a subset of the secret keys, their ability to decrypt is strictly limited to a specific "direct-prefix" model where they can only recover the initial blocks of a message if the path happens to land on those known keys; this does not bound the capabilities of an unrestricted adversary.

The paper also addresses why this new approach was necessary by looking at a previous attempt by the same researcher. An earlier version of the idea tried to use a more complex geometric shape, but it failed because it accidentally revealed a part of the secret message in plain sight. The new design fixes this by ensuring the message never multiplies a public object, which was the cause of the leak in the old version. Instead, the message simply selects between two options, keeping the relationship between the secret and the public data noisy and hidden. The researcher also explored what would happen if the system tried to move the keys around in a more complex way, like twisting the path as it goes. They found that doing so without breaking the mathematical rules of the system is extremely difficult, as it would require the keys to change in ways that are almost impossible to achieve with whole numbers.

Ultimately, this work presents a new architecture for encryption rather than a finished product ready for immediate use. It offers a fresh perspective on how to link keys together, using the message itself to drive the process. The researcher provides detailed blueprints for how to build the system, including specific numbers for the size of the keys and the amount of noise required. They also provide a way for others to test the system and verify the results. While the system does not yet have a proven security level against all possible attacks, and it lacks features like message authentication or chosen-ciphertext security, it stands as a rigorous mathematical exploration of a new way to hide data. It shows that by letting the message choose its own path through a forest of keys, one can create a system that is both highly reliable and structurally distinct from the static methods used today.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →